I made user authenticaton done against mysql via pam. The problem is the user name, say user1, and its password in default domain can be used to log into the same username account of other virtual domains by putting [EMAIL PROTECTED] in client programs like outlook express. Is this a bug? If not, what is the right form to store user name of the default domain in mysql? I just put user1 because with [EMAIL PROTECTED] I could not authenticate with outlook express. --- Cyrus Home Page: http://asg.web.cmu.edu/cyrus Cyrus Wiki/FAQ: http://cyruswiki.andrew.cmu.edu List Archives/Info: http://asg.web.cmu.edu/cyrus/mailing-list.html